System and method for regulated message routing and global policy enforcement

ABSTRACT

A system for regulated message routing and global policy enforcement. The transmission of data across a network is bound by policies administered by individuals, organizations, and governments. The system continuously tracks current world government regulations, is easily programmed to incorporate organization best practices and policies, and will automatically handle network traffic routing such that all regulations are fulfilled at all stages of transmission and compliance is recorded for possible later forensic or regulatory analysis.

CROSS-REFERENCE TO RELATED APPLICATIONS

Application No. Date Filed Title Current Herewith HYBRID SYSTEM FOR THE application PROTECTION AND SECURE DATA TRANSPORTATION OF CONVERGENT OPERATIONAL TECHNOLOGY AND INFORMATIONAL TECHNOLOGY NETWORKS Is a continuation-in-part of: 15/931,534 May 13, 2020 SECURE POLICY-CONTROLLED PROCESSING AND AUDITING ON REGULATED DATA SETS which is a continuation-in-part of: 16/777,270 Jan. 30, 2020 CYBERSECURITY PROFILING AND RATING USING ACTIVE AND PASSIVE EXTERNAL RECONNAISSANCE which is a continuation-in-part of: 16/720,383 Dec. 19, 2019 RATING ORGANIZATION CYBERSECURITY USING ACTIVE AND PASSIVE EXTERNAL RECONNAISSANCE which is a continuation of: 15/823,363 Nov. 27, 2017 RATING ORGANIZATION Patent Issue Date CYBERSECURITY USING ACTIVE 10,560,483 Feb. 11, 2020 AND PASSIVE EXTERNAL RECONNAISSANCE which is a continuation-in-part of: 15/725,274 Oct. 4, 2017 APPLICATION OF ADVANCED Patent Issue Date CYBERSECURITY THREAT 10,609,079 Mar. 31, 2020 MITIGATION TO ROGUE DEVICES, PRIVILEGE ESCALATION, AND RISK-BASED VULNERABILITY AND PATCH MANAGEMENT which is a continuation-in-part of: 15/655,113 Jul. 20, 2017 ADVANCED CYBERSECURITY Patent Issue Date THREAT MITIGATION USING 10,735,456 Aug. 4, 2020 BEHAVIORAL AND DEEP ANALYTICS which is a continuation-in-part of: 15/616,427 Jun. 7, 2017 RAPID PREDICTIVE ANALYSIS OF VERY LARGE DATA SETS USING AN ACTOR-DRIVEN DISTRIBUTED COMPUTATIONAL GRAPH and is also a continuation-in-part of: 15/237,625 Aug. 15, 2016 DETECTION MITIGATION AND Patent Issue Date REMEDIATION OF CYBERATTACKS 10,248,910 Apr. 2, 2019 EMPLOYING AN ADVANCED CYBER-DECISION PLATFORM which is a continuation-in-part of: 15/206,195 Jul. 8, 2018 ACCURATE AND DETAILED MODELING OF SYSTEMS WITH LARGE COMPLEX DATASETS USING A DISTRIBUTED SIMULATION ENGINE which is a continuation-in-part of: 15/186,453 Jun. 18, 2016 SYSTEM FOR AUTOMATED CAPTURE AND ANALYSIS OF BUSINESS INFORMATION FOR RELIABLE BUSINESS VENTURE OUTCOME PREDICTION which is a continuation-in-part of: 15/166,158 May 26, 2016 SYSTEM FOR AUTOMATED CAPTURE AND ANALYSIS OF BUSINESS INFORMATION FOR SECURITY AND CLIENT-FACING INFRASTRUCTURE RELIABILITY which is a continuation-in-part of: 15/141,752 Apr. 28, 2016 SYSTEM FOR FULLY INTEGRATED CAPTURE, AND ANALYSIS OF BUSINESS INFORMATION RESULTING IN PREDICTIVE DECISION MAKING AND SIMULATION which is a continuation-in-part of: 15/091,563 Apr. 5, 2016 SYSTEM FOR CAPTURE, ANALYSIS Patent Issue Date AND STORAGE OF TIME SERIES 10,204,147 Feb. 12, 2019 DATA FROM SENSORS WITH HETEROGENEOUS REPORT INTERVAL PROFILES and is also a continuation-in-part of: 14/986,536 Dec. 31, 2015 DISTRIBUTED SYSTEM FOR LARGE Patent Issue Date VOLUME DEEP WEB DATA 10,210,255 Feb. 19, 2019 EXTRACTION and is also a continuation-in-part of: 14/925,974 Oct 28, 2015 RAPID PREDICTIVE ANALYSIS OF VERY LARGE DATA SETS USING THE DISTRIBUTED COMPUTATIONAL GRAPH Current Herewith HYBRID SYSTEM FOR THE application PROTECTION AND SECURE DATA TRANSPORTATION OF CONVERGENT OPERATIONAL TECHNOLOGY AND INFORMATIONAL TECHNOLOGY NETWORKS Is a continuation-in-part of: 15/931,534 May 13, 2020 SECURE POLICY-CONTROLLED PROCESSING AND AUDITING ON REGULATED DATA SETS which is a continuation-in-part of: 15/683,765 Aug. 22, 2017 PREDICTIVE LOAD BALANCING FOR A DIGITAL ENVIRONMENT which is a continuation-in-part of: 15/409,510 Jan. 18, 2017 MULTI-CORPORATION VENTURE PLAN VALIDATION EMPLOYING AN ADVANCED DECISION PLATFORM which is a continuation-in-part of: 15/379,899 Dec. 15, 2016 INCLUSION OF TIME SERIES GEOSPATIAL MARKERS IN ANALYSES EMPLOYING AN ADVANCED CYBER-DECISION PLATFORM which is a continuation-in-part of: 15/376,657 Dec. 13, 2016 QUANTIFICATION FOR Patent Issued Date INVESTMENT VEHICLE 10,402,906 Sep. 3, 2019 MANAGEMENT EMPLOYING AN ADVANCED DECISION PLATFORM which is a continuation-in-part of: 15/237,625 Aug. 15, 2016 DETECTION MITIGATION AND Patent Issue Date REMEDIATION OF CYBERATTACKS 10248910 Apr. 2, 2019 EMPLOYING AN ADVANCED CYBER-DECISION PLATFORM Current Herewith HYBRID SYSTEM FOR THE application PROTECTION AND SECURE DATA TRANSPORTATION OF CONVERGENT OPERATIONAL TECHNOLOGY AND INFORMATIONAL TECHNOLOGY NETWORKS Is a continuation-in-part of: 15/931,534 May 13, 2020 SECURE POLICY-CONTROLLED PROCESSING AND AUDITING ON REGULATED DATA SETS which is a continuation-in-part of: 16/718,906 Dec. 18, 2019 PLATFORM FOR HIERARCHY COOPERATIVE COMPUTING which is a continuation of: 15/879,182 Jan. 24, 2018 PLATFORM FOR HIERARCHY Patent Issue Date COOPERATIVE COMPUTING 10,514,954 Dec. 24, 2019 which is a continuation-in-part of: 15/850,037 Dec. 21, 2017 ADVANCED DECENTRALIZED FINANCIAL DECISION PLATFORM which is a continuation-in-part of: 15/673,368 Aug. 9, 2017 AUTOMATED SELECTION AND PROCESSING OF FINANCIAL MODELS which is a continuation-in-part of: 15/376,657 Dec. 13, 2016 QUANTIFICATION FOR Patent Issue Date INVESTMENT VEHICLE 10,402,906 Sep. 3, 2019 MANAGEMENT EMPLOYING AN ADVANCED DECISION PLATFORM Current Herewith HYBRID SYSTEM FOR THE application PROTECTION AND SECURE DATA TRANSPORTATION OF CONVERGENT OPERATIONAL TECHNOLOGY AND INFORMATIONAL TECHNOLOGY NETWORKS Is a continuation-in-part of: 15/931,534 May 13, 2020 SECURE POLICY-CONTROLLED PROCESSING AND AUDITING ON REGULATED DATA SETS which is a continuation-in-part of: 16/718,906 Dec. 18, 2019 PLATFORM FOR HIERARCHY COOPERATIVE COMPUTING which is a continuation of: 15/879,182 Jan. 24, 2018 PLATFORM FOR HIERARCHY Patent Issue Date COOPERATIVE COMPUTING 10,514,954 Dec. 24, 2019 which is a continuation-in-part of: 15/850,037 Dec. 21, 2017 ADVANCED DECENTRALIZED FINANCIAL DECISION PLATFORM which is a continuation-in-part of: 15/489,716 Apr. 17, 2017 REGULATION BASED SWITCHING SYSTEM FOR ELECTRONIC MESSAGE ROUTING which is a continuation-in-part of: 15/409,510 Jan. 18, 2017 MULTI-CORPORATION VENTURE PLAN VALIDATION EMPLOYING AN ADVANCED DECISION PLATFORM Current Herewith HYBRID SYSTEM FOR THE application PROTECTION AND SECURE DATA TRANSPORTATION OF CONVERGENT OPERATIONAL TECHNOLOGY AND INFORMATIONAL TECHNOLOGY NETWORKS Is a continuation-in-part of: 15/931,534 May 13, 2020 SECURE POLICY-CONTROLLED PROCESSING AND AUDITING ON REGULATED DATA SETS which is a continuation-in-part of: 15/905,041 Feb. 28, 2018 AUTOMATED SCALABLE Patent Issue Date CONTEXTUAL DATA COLLECTION 10,706,063 Jul. 7, 2020 AND EXTRACTION SYSTEM which is a continuation-in-part of: 15/237,625 Aug. 15, 2016 DETECTION MITIGATION AND Patent Issue Date REMEDIATION OF CYBERATTACKS 10,248,910 Apr. 2, 2019 EMPLOYING AN ADVANCED CYBER-DECISION PLATFORM Current Herewith HYBRID SYSTEM FOR THE application PROTECTION AND SECURE DATA TRANSPORTATION OF CONVERGENT OPERATIONAL TECHNOLOGY AND INFORMATIONAL TECHNOLOGY NETWORKS Is a continuation-in-part of: 15/931,534 May 13, 2020 SECURE POLICY-CONTROLLED PROCESSING AND AUDITING ON REGULATED DATA SETS which is a continuation-in-part of: 16/191,054 Nov. 14, 2018 SYSTEM AND METHOD FOR Patent Issue Date COMPREHENSIVE DATA LOSS 10,681,074 Jun. 9, 2020 PREVENTION AND COMPLIANCE MANAGEMENT which is a continuation-in-part of: 15/655,113 Jul. 20,2017 ADVANCED CYBERSECURITY Patent Issue Date THREAT MITIGATION USING 10,735,456 Aug. 4, 2020 BEHAVIORAL AND DEEP ANALYTICS Current Herewith HYBRID SYSTEM FOR THE application PROTECTION AND SECURE DATA TRANSPORTATION OF CONVERGENT OPERATIONAL TECHNOLOGY AND INFORMATIONAL TECHNOLOGY NETWORKS Is a continuation-in-part of: 15/931,534 May 13, 2020 SECURE POLICY-CONTROLLED PROCESSING AND AUDITING ON REGULATED DATA SETS which is a continuation-in-part of: 16/654,309 Oct. 16, 2019 SYSTEM AND METHOD AUTOMATED ANALYSIS OF LEGAL DOCUMENTS WITHIN AND ACROSS SPECIFIC FIELDS which is a continuation-in-part of: 15/847,443 Dec. 19, 2017 SYSTEM AND METHOD FOR AUTOMATIC CREATION OF ONTOLOGICAL DATABASES AND SEMANTIC SEARCHING which is a continuation-in-part of: 15/790,457 Oct. 23, 2017 DISTRIBUTABLE MODEL WITH BIASES CONTAINED WITHIN DISTRIBUTED DATA which claims benefit of, and priority to: 62/568,298 Oct. 4, 2017 DISTRIBUTABLE MODEL WITH BIASES CONTAINED IN DISTRIBUTED DATA and is also a continuation-in-part of: 15/790,327 Oct. 23, 2017 DISTRIBUTABLE MODEL WITH DISTRIBUTED DATA which claims benefit of, and priority to: 62/568,291 Oct. 4, 2017 DISTRIBUTABLE MODEL WITH DISTRIBUTED DATA and is also a continuation-in-part of: 15/141,752 Apr. 28, 2016 SYSTEM FOR FULLY INTEGRATED CAPTURE, AND ANALYSIS OF BUSINESS INFORMATION RESULTING IN PREDICTIVE DECISION MAKING AND SIMULATION and is also a continuation-in-part of: 15/616,427 Jun. 7, 2017 RAPID PREDICTIVE ANALYSIS OF VERY LARGE DATA SETS USING AN ACTOR-DRIVEN DISTRIBUTED COMPUTATIONAL GRAPH which is a continuation-in-part of: 14/925,974 Oct. 28, 2015 RAPID PREDICTIVE ANALYSIS OF VERY LARGE DATA SETS USING THE DISTRIBUTED COMPUTATIONAL GRAPH Current Herewith HYBRID SYSTEM FOR THE application PROTECTION AND SECURE DATA TRANSPORTATION OF CONVERGENT OPERATIONAL TECHNOLOGY AND INFORMATIONAL TECHNOLOGY NETWORKS Is a continuation-in-part of: 15/931,534 May 13, 2020 SECURE POLICY-CONTROLLED PROCESSING AND AUDITING ON REGULATED DATA SETS which is a continuation-in-part of: 16/654,309 Oct. 16, 2019 SYSTEM AND METHOD AUTOMATED ANALYSIS OF LEGAL DOCUMENTS WITHIN AND ACROSS SPECIFIC FIELDS which is a continuation-in-part of: 15/847,443 Dec. 19, 2017 SYSTEM AND METHOD FOR AUTOMATIC CREATION OF ONTOLOGICAL DATABASES AND SEMANTIC SEARCHING which is a continuation-in-part of: 15/616,427 Jun. 7, 2017 RAPID PREDICTIVE ANALYSIS OF VERY LARGE DATA SETS USING AN ACTOR-DRIVEN DISTRIBUTED COMPUTATIONAL GRAPH and is also a continuation-in-part of: 15/489,716 Apr. 17, 2017 REGULATION BASED SWITCHING SYSTEM FOR ELECTRONIC MESSAGE ROUTING Current Herewith HYBRID SYSTEM FOR THE application PROTECTION AND SECURE DATA TRANSPORTATION OF CONVERGENT OPERATIONAL TECHNOLOGY AND INFORMATIONAL TECHNOLOGY NETWORKS Is a continuation-in-part of: 15/931,534 May 13, 2020 SECURE POLICY-CONTROLLED PROCESSING AND AUDITING ON REGULATED DATA SETS which is a continuation-in-part of: 16/660,727 Oct. 22, 2019 HIGHLY SCALABLE DISTRIBUTED CONNECTION INTERFACE FOR DATA CAPTURE FROM MULTIPLE NETWORK SERVICE SOURCES which is a continuation of: 15/229,476 Aug. 5, 2016 HIGHLY SCALABLE DISTRIBUTED Patent Issue Date CONNECTION INTERFACE FOR 10,454,791 Oct. 22, 2019 DATA CAPTURE FROM MULTIPLE NETWORK SERVICE SOURCES which is a continuation-in-part of: 15/206,195 Jul. 8, 2016 ACCURATE AND DETAILED MODELING OF SYSTEMS WITH LARGE COMPLEX DATASETS USING A DISTRIBUTED SIMULATION ENGINE the entire specification of each of which is incorporated herein by reference.

BACKGROUND OF THE INVENTION Field of the Invention

The present invention is in the field of message routing, more specifically, the fields of data transfer enforcement and networking policies.

Discussion of the State of the Art

The legal, regulatory, and cultural expectations of data aggregation and processing oriented practices are growing increasing complex. Unfortunately, due to this complexity, technology companies are failing to comply with governments despite the expenditure of costly amounts of workforce effort and budget capital. The current continuing spiral is now serving to increasingly erode the public's trust. Global cloud providers (e.g. AWS) address these pressures by creating availability zones inside countries or homogenous regulatory environments to support emerging regulations and requirements but ultimately fail to provide a regulated experience outside of their offerings. As governments continue to enforce their sovereign rights and as case law evolves, the compounding effects of legislation, sensitive information exposure, and increasing legal exposure resultant from network exploits accelerates. These events assure that all will continue to see strong balkanization of the once homogenous technology infrastructure.

Furthermore, current networking technology and infrastructure relies heavily on packet routing that reasons about the units that compose a message, whereas what is needed is message routing that reasons about the contents of a message. Common routers and switches reason about packet flow, but do not reason about message flow. One reason why this hasn't been addressed is because common routers lack the sophistication and context to reason about application-level protocols which are needed to address the concerns of data sovereignty, residency, and localization.

What is needed is a system for regulated message routing and global policy enforcement. Whereby the transmission of data across a network is bound by policies administered by individuals, organizations, and governments. The system continuously tracks current world government regulations, is easily programmed to incorporate organization best practices and policies, and will automatically handle network traffic routing such that all regulations are fulfilled at all stages of transmission and compliance is recorded for possible later forensic or regulatory analysis.

SUMMARY OF THE INVENTION

Accordingly, the inventor has conceived and reduced to practice, a system for regulated message routing and global policy enforcement. The transmission of data across a network is bound by policies administered by individuals, organizations, and governments. The system continuously tracks current world government regulations, is easily programmed to incorporate organization best practices and policies, and will automatically handle network traffic routing such that all regulations are fulfilled at all stages of transmission and compliance is recorded for possible later forensic or regulatory analysis.

According to a preferred embodiment of the invention, a message routing system for global policy enforcement is disclosed, comprising: a message-layer router comprising at least a plurality of programming instructions stored in a memory of, and operating on at least one processor of, a computing device, wherein the plurality of programming instructions, when operating on the at least one processor, cause the computing device to: store a plurality of regulations and policy rules regarding a plurality of individuals, organizations, and governments; search for and implement updates to the plurality of regulations and policy rules; receive a network-bound message from a first networked device, the network-bound message intended for a second networked device; inspect the network-bound message for attributes related to individuals, organizations, and governments; apply the plurality of regulation and policy rules to the network-bound message, wherein the applied rules correspond to the attributes related to individuals, organizations, and governments in the network-bound message; confirm that the first networked device and the second networked device comply with the regulation and policy rules applied to the network-bound message; and release the network-bound message for transmission to the second networked device.

According to another preferred embodiment of the invention, a method for message routing for global policy enforcement comprising the steps of: storing a plurality of regulations and policy rules regarding a plurality of individuals, organizations, and governments; searching for and implementing updates to the plurality of regulations and policy rules; receiving a network-bound message from a first networked device, the network-bound message intended for a second networked device; inspecting the network-bound message for attributes related to individuals, organizations, and governments; applying the plurality of regulation and policy rules to the network-bound message, wherein the applied rules correspond to the attributes related to individuals, organizations, and governments in the network-bound message; confirming that the first networked device and the second networked device comply with the regulation and policy rules applied to the network-bound message; and releasing the network-bound message for transmission to the second networked device.

According to various aspects of the invention: an embodiment further comprising a ledger to immutably record changes to and transactions of the network-bound message; at least a portion of the plurality of regulation and policy rules are issued by at least one government entity from at least one geographical region; the message-layer router is integrated into a layer two or layer three switch; the network-bound message operates on the ten-layer standard open system interconnection model; the message-layer router determines if all intermediary networked devices comply with the plurality of applied regulation and policy rules; message-layer router confirms if one or more users are compliant with the plurality of regulation and policy rules; the message-layer router enforces routing based on cybersecurity threat indicators; the message-layer router is a software-based application; the message-layer router also reads layers two and three of the open interconnection system model.

BRIEF DESCRIPTION OF THE DRAWING FIGURES

The accompanying drawings illustrate several embodiments of the invention and, together with the description, serve to explain the principles of the invention according to the embodiments. One skilled in the art will recognize that the particular embodiments illustrated in the drawings are merely exemplary, and are not intended to limit the scope of the present invention.

FIG. 1 is a diagram of an exemplary architecture of a message-layer routing system per an embodiment.

FIG. 2 is a flow diagram of an exemplary function of a regulatory message-layer message routing system in routing sensitive electronic messages per an embodiment.

FIG. 3A is a diagram showing an exemplary representation of the media layers from the ten-layer OSI model.

FIG. 3B is a diagram showing an exemplary representation of the host layers from the ten-layer OSI model.

FIG. 3C is a diagram showing an exemplary representation of the payload layers from the ten-layer OSI model.

FIG. 4 is a comparison of select features of common routers and an embodiment router.

FIG. 5A and FIG. 5B are process diagrams of a simplified OSI 8/9/10 message header and example programming structure per an embodiment.

FIG. 6 is a diagram illustrating the use of routing regulatory labels to create availability zones.

FIG. 7 is a block diagram illustrating an exemplary hardware architecture of a computing device used in various embodiments of the invention.

FIG. 8 is a block diagram illustrating an exemplary logical architecture for a client device, according to various embodiments.

FIG. 9 is a block diagram illustrating an exemplary architectural arrangement of clients, servers, and external services, according to various embodiments.

FIG. 10 is another block diagram illustrating an exemplary hardware architecture of a computing device used in various embodiments.

DETAILED DESCRIPTION

The inventor has conceived, and reduced to practice, a system for regulated message routing and global policy enforcement. The transmission of data across a network is bound by policies administered by individuals, organizations, and governments. The system continuously tracks current world government regulations, is easily programmed to incorporate organization best practices and policies, and will automatically handle network traffic routing such that all regulations are fulfilled at all stages of transmission and compliance is recorded for possible later forensic or regulatory analysis.

Message routing reasons about the assembled contents of a message. Packet routing reasons about the units that compose a message. Common routers and switches reason about packet flow, but do not reason about message flow. Common routers lack the sophistication and context to reason about application-level protocols. The disclosed invention focuses on routing messages between entities and between physical locations overcoming the barrier of common routers lack of implementation for new governmental and global regulations on data traffic. To facilitate this, message label switches (MLS) facilitates routers that can reason about Application-level protocols and extended OSI Labels. Each MLS facilitates policy expression evaluation to determine whether a payload can pass between a source and a receiver.

In a typical embodiment, network-bound messages with sensitive information containing payloads are received with information regulation identifying and information policy identifying labels in addition to source router identifying label all of which may correspond to OSI model layer 8, 9 and 10 corresponding information in the form of “<GOVERNMENT>.<ORGANIZATION>.<INDIVIDUAL>” for routing functions and “<CLASS>.<METHOD>.<STREAM>” for payload characteristics although other configurations may be used systemically as needed. Regulation compliance pertaining to payload contents at all stages of both transmission and receiving entity information delivery is controlled by up-to-date software rules entered into a highly secure, ledger-bound, regulation and policy data store. During transmission, both source and receiver specific for all applicable regulation and policy rules of the current message payload may control delivery path of the regulated message and the suitability of the intended recipient entity using additional recipient entity credential data local to the message destination systems. All stages of payload analysis, label application, transmission and delivery to the recipient entity of each service system handled payload may be logged for subsequent forensic or regulatory compliance analysis.

One or more different inventions may be described in the present application. Further, for one or more of the inventions described herein, numerous alternative embodiments may be described; it should be understood that these are presented for illustrative purposes only. The described embodiments are not intended to be limiting in any sense. One or more of the inventions may be widely applicable to numerous embodiments, as is readily apparent from the disclosure. In general, embodiments are described in sufficient detail to enable those skilled in the art to practice one or more of the inventions, and it is to be understood that other embodiments may be utilized and that structural, logical, software, electrical and other changes may be made without departing from the scope of the particular inventions. Accordingly, those skilled in the art will recognize that one or more of the inventions may be practiced with various modifications and alterations. Particular features of one or more of the inventions may be described with reference to one or more particular embodiments or figures that form a part of the present disclosure, and in which are shown, by way of illustration, specific embodiments of one or more of the inventions. It should be understood, however, that such features are not limited to usage in the one or more particular embodiments or figures with reference to which they are described. The present disclosure is neither a literal description of all embodiments of one or more of the inventions nor a listing of features of one or more of the inventions that must be present in all embodiments.

Headings of sections provided in this patent application and the title of this patent application are for convenience only, and are not to be taken as limiting the disclosure in any way.

Devices that are in communication with each other need not be in continuous communication with each other, unless expressly specified otherwise. In addition, devices that are in communication with each other may communicate directly or indirectly through one or more intermediaries, logical or physical.

A description of an embodiment with several components in communication with each other does not imply that all such components are required. To the contrary, a variety of optional components may be described to illustrate a wide variety of possible embodiments of one or more of the inventions and in order to more fully illustrate one or more aspects of the inventions. Similarly, although process steps, method steps, algorithms or the like may be described in a sequential order, such processes, methods and algorithms may generally be configured to work in alternate orders, unless specifically stated to the contrary. In other words, any sequence or order of steps that may be described in this patent application does not, in and of itself, indicate a requirement that the steps be performed in that order. The steps of described processes may be performed in any order practical. Further, some steps may be performed simultaneously despite being described or implied as occurring sequentially (e.g., because one step is described after the other step). Moreover, the illustration of a process by its depiction in a drawing does not imply that the illustrated process is exclusive of other variations and modifications thereto, does not imply that the illustrated process or any of its steps are necessary to one or more of the invention(s), and does not imply that the illustrated process is preferred. Also, steps are generally described once per embodiment, but this does not mean they must occur once, or that they may only occur once each time a process, method, or algorithm is carried out or executed. Some steps may be omitted in some embodiments or some occurrences, or some steps may be executed more than once in a given embodiment or occurrence.

When a single device or article is described, it will be readily apparent that more than one device or article may be used in place of a single device or article. Similarly, where more than one device or article is described, it will be readily apparent that a single device or article may be used in place of the more than one device or article.

The functionality or the features of a device may be alternatively embodied by one or more other devices that are not explicitly described as having such functionality or features. Thus, other embodiments of one or more of the inventions need not include the device itself.

Techniques and mechanisms described or referenced herein will sometimes be described in singular form for clarity. However, it should be noted that particular embodiments include multiple iterations of a technique or multiple manifestations of a mechanism unless noted otherwise. Process descriptions or blocks in figures should be understood as representing modules, segments, or portions of code which include one or more executable instructions for implementing specific logical functions or steps in the process. Alternate implementations are included within the scope of embodiments of the present invention in which, for example, functions may be executed out of order from that shown or discussed, including substantially concurrently or in reverse order, depending on the functionality involved, as would be understood by those having ordinary skill in the art.

Definitions

As used herein, a “message-layer router” is a networking device which works on layers of a data packet corresponding to individuals, organizations, and governments. Similar to devices such as a data switch which operates on the second layer (MAC addresses) of the open interconnection systems (OSI) model and that of layer three switches which work on layer three (IP addresses), a “message-layer switch” works on layers eight, nine, and ten (individual, organizational, governmental respectively). A “message-layer router” may also be implemented using other models than the OSI model and is not limited to one or the other.

As used herein, a “network-bound message” is a series of bits formed into a data packet, otherwise known as a message, which is intended to leave the originating computing device to another computing device. The network in which the message travels may be a hardline (e.g., ethernet, serial, etc.) or wireless communication network.

As used herein, a “networked device” is a computing device connected either wirelessly or wired to another computing device. Any number of other “networked devices” may exist between any two “networked devices” thus forming a network of “networked devices”.

As used herein, the “OSI model” characterizes computing functions into a universal set of rules and requirements in order to support interoperability between different products and software. The model partitions the flow of data in a communication system into seven or ten layers, from the physical implementation of transmitting bits across a communications medium to a representation of data of a distributed application to the highest-level concerning governmental regulations. Each intermediate layer serves a class of functionality to the layer above it and is served by the layer below it. Classes of functionality are realized in software by standardized communication protocols.

Conceptual Architecture

FIG. 1 is a diagram of an exemplary architecture of a message-layer routing system 100 per an embodiment. The embodiment works to simplify the exchange of messages containing sensitive and regulation-controlled information by allowing routing boundaries, rules, policies and router handling programming for each to be centrally entered and then dictate message flow for the entire controlled WAN. The messages may enter the embodiment from external sources through a message label switch (MLS) aware messaging client 105 which is so named as it may set up routing paths based upon message payload content dictated labels. The labels may contain policy and regulatory information pertaining to an individual and pertaining to similar information connected to entities at an organization or government level. These messages may arrive at the messaging client already possessing a label designation for the source router, which may be software based, to be employed to send it, one or more labels disclosing the payload and thus designating the payload router, which again may be software based, to be targeted and a destination location indication of where the author requests the message sent 105. Designation of formal destination or “receiver” MLS aware router may be made by an MLS addresser module 110 which selects a receiver router for the message at least partially based upon the current rule, policy and regulation entries stored in an MLS rules write ahead data store 140. Once addressed with a receiving router, the message, now with its source router, payload router and receiver router designated, will pass to the source exchange module 115 which may serve as a message aggregator for the specified MLS source router 160. The source router, which may be software based may be implemented and configured upon arrival of a message payload requiring specific regulatory of policy dictated capabilities. Also shown is an MLS type source label which indicates an individual (IND), organization (ORG) and government (GOV) labeling structure 115 a where information about the sender, the sender's organization and the sender's country or geographical zone may be disclosed. For example, “US.ABC1234MHOSP.NKEANMD” may identify Dr. Noa Kean at ABC1234 Memorial Hospital in the US. Each portion of this label may invoke pre-engineered programming rules within the regulation-based message routing system that effect the payloads that may be sent, who may send the payload and the receivers to which they may be transmitted. At this stage in the process a pre-programmed rule such as but not limited to whether NKEANMD may send messages from the source router may be exercised. If this example rule, together with other possible source router rules are passed, the message may be bound to the source router 160. A next process to occur prior to transmission of the message may be the analysis of the payload label plus any other policy markers that may accompany the message header in preferred aspects, in a payload exchange module 165. The payload label may of be the form “payload class”<CLASS>, “payload method”<METHOD>, and “payload origin”<STDIN|OUT|ERR> 165 a. This label, like that for binding the source router, invokes pre-engineered programming pertaining to the characteristics of the payload contained in the message as disclosed by the payload label and in at least some instances, additional policy markers attached to the message possibly in a header stack. One of a great plurality of examples may be payload containing a HIPAA regulated patient record possessing a “PRECORD.TRANSFER.STDOUT” label. Some pre-programmed rules that may be applied are whether the sending individual, Dr. Kean in our example, may legally access and send the payload. A failure to pass this test or other tests, individually or in combination (where the ‘AND’ conjunctive is implicitly in effect by default but ‘OR’ disjunctive may also be used) may stop the transaction. Another rule may address whether ABC1234 Memorial Hospital may send the HIPAA regulated payload to the intended recipient and a last pre-programmed rule may determine whether the recipient has the credentials to receive the HIPAA protected payload. If all payload routing rules and policies are met, the message will be bound to the payload router 170, which may be implemented and configured on-the-fly and the message may then be transmitted to the receiver exchange module 175 which serves as an aggregator for incoming messages to that router using a more global reverse receiver message, which while it has the general form of <GOV>.<ORG>.<IND> may use a more generic form of the label where the individual recipient is programmatically substituted with a generic, all inclusive, identifier (*).

The transfer to the receiver router, more than others, may involve the transmission of the message from one regulation-based message routing system, which itself may be highly distributed to another distributed regulation-based message routing system, possibly requiring a plurality of intermediary hops. Due to the use of message layer routing (OSI 7/8) instead of packet layer routing (OSI 3) and a networking protocol, multi-protocol label switching (MPLS), which, among a plurality of other capabilities, may allow an edge router, which the source router may be considered an example, to specify the router for the next hop in the path to the ultimate destination as well as possibly designating the ultimate destination router. At each intermediate router along the pathway the current router may strip its designation from the list and add that of the chosen next hop router in its place. An extension of MPLS may also allow labels constraining the travel of the routed message to routers with specific capabilities, possibly security protocols or message integrity related, or geographical zones, for instance only within the US, to be placed on the label stack such that only network routers with those characteristics may be used. This feature of adding policy labels may allow individuals, organizations and governments using regulation-based message routing system services to easily ensure that their network messages fulfill all necessary data transfer laws and regulations.

While <GOV>.<ORG>.<IND>115 a and <CLASS>.<METHOD>.<STDIN|OUT|ERR>165 a may be expected as common MLS router and MLS payload label sets, other embodiments may use labels having different informational constituents that are known to that messaging network system but are not <GOV>.<ORG>.<IND>or <CLASS>.<METHOD>.<STDIN|OUT|ERR> as the invention does not specify what label types must be used or the number of label types that constitute a valid label. This feature provides a greatly expanded set of the types of information may be used and may provide a large degree of flexibility for evolution of the system as laws, regulations and corporate practices continue to change.

Messages sent from a source to a receiver successfully are aggregated in the receiver router's receiver exchange module 175. There, label constituents and associated policy labels may be inspected to confirm that the receiving government or organization facility is authorized to receive the payload. For example the message from “US.ABC1234MHOSP.NKEANMD” that apparently includes a patient record as the payload “PRECORD.TRANSFER.STDOUT.” As the receiver may be another hospital in the US, “US.WXYZ54321MHOSP.*” 175 a which may be programmatically implemented on a physical node on-the-fly so most likely has all processes for the receipt of HIPAA governed materials already in place, the message is expected to be received and placed in a client upstream payload exchange module where the ability of the receiving individual, Dr. Jo Wilson, may be confirmed using the payload label 185 a before being placed in a client federated payload exchange module 190 for the recipient, J. Wilson, MD. under the handling requirements for the materials listed in the payload label 190 a. In cases where a single message arrives with more than one recipient, the entire message may be duplicated such that each recipient gets an autonomous copy of the message which may be modified or tracked per programmed rules of the embodiment.

Laws, regulations and both corporate and network service policies may change significantly over time. Embodiments of the regulation-based message routing system provides the ability to write routing rules using a plurality of programming languages and may have extension libraries for at least a subset of those languages to allow for the precise and efficient codification of message handling actions such that all nuances of these important, potentially complex directives may be accurately represented. Programming of route or policy directives may be accomplished remotely 145 in most embodiments using programming interface clients specific for either route rule command entry 120 or route policy command entry 130. Certain aspects may use only direct MLS programming client connections for route rule programming changes, policy rule programming changes or both to maintain a higher level of security. MLS route rule programming is normalized in an MLS route writing module 125 and, upon confirmation of the authority of the programming author by the MLS route writing module may be committed to an append-only MLS rules write-ahead data store 140 for persistent storage. Similarly, MLS policy rule programming is normalized in an MLS policy writing module 135 and, upon confirmation that the author of the new programming is authorized to add rule code to the routing system, committed to the append-only MLS rules write ahead data store 140 for persistent storage.

For maximal forensic analysis opportunity and change tracking capabilities, embodiments of the write ahead log 140, which hold the current, working, set of both routing and policy rules as well as records of all previous rules may incorporate a distributed ledger. One distributed ledger mechanism that may be used are available blockchains such as BITCOIN™, FACTOM™, LBRY™ and BIGCHAINDB™ among others where any modification of previous entries once committed is extremely difficult, if not impossible. While these blockchain services currently suffer from low data storage ceilings and may require purchase of cryptocurrency per unit storage, this drawback may be overcome by embodiments by combining secured, conventional database storage to store the full rule programming information while using one of the blockchain services to store hash recorded information to serve as the ledger. Another mechanism for secure, persistent write ahead log change tracking that may be used by embodiments is to control the change of route and policy rule programming through smart contracts or some other, similar vehicle known to those skilled in the art.

Translation of the current router and policy rules of the write ahead log 140 into the router 160, 170, 180 behavior of the embodiment may be performed by the MLS route module 150 for router rules and the MLS policy module 155 for policy expressions. These modules may perform updates by destroying existing software-based routers and creating new routers compliant for the newest rule state or by updating the existing router or routers to reflect the current rule status based upon instantaneous embodiment conditions or implementation. This allows for the most efficient rule entry to rule implementation pathway based upon the specific needs of the embodiment.

As embodiments are designed to be a distributed service, each of the described features may individually take place on different physical servers possible residing in separate, distant, data centers.

As an example of a preferred embodiment, a message routing system 100 for global policy enforcement comprises a message-layer router that can read from layers eight, nine, and ten of the OSI model, however, other embodiment may use other models or protocols as known in the art. Stored in the memory of the message-layer router may be a plurality of regulations and policy rules regarding a plurality of individuals, organizations, and governments. In some embodiments, these may be manually entered in, automatically pulled or pushed from a network or the Internet, or a combination of manual and automatic entry. A preferred embodiment also performs periodic searches for updates and implements any updates to the plurality of regulations and policy rules. The period for which the system automatically performs these updates may be as small as one clock cycle of the computing device or as large as one year, or as the implementor of the system desires.

When a computing device on a network, otherwise a networked device, forms a data packet intended for transmission to a computing device other than itself, information about individuals, organizations, and governments, are inserted, appended, or otherwise affixed to the layers of that data packet such that when the message-layer router 100 receives the network-bound message (data packet) from the first networked device, the message-layer router 100 will inspect the network-bound message layers for attributes related to individuals, organizations, and governments. Using the attributes, the message-layer router will apply the plurality of regulation and policy rules to the network-bound message, wherein the applied rules correspond to the attributes related to individuals, organizations, and governments such that any non-compliance to those rules deny transmission of said data packet (network-bound message). However, upon confirmation that the first networked device, the second networked device, and the message comply with the regulation and policy rules, the message-layer router 100 releases the network-bound message for transmission to the second networked device.

One embodiment comprises a ledger module to immutably record changes to and transactions of the network-bound message. The ledger may be integrated into the message-layer router 100 or the message-layer router 100 may send the changes to and transactions of the network-bound message to a ledger service, cloud-based ledger, decentralized ledger, or other ledger-type store. Various aspects of the invention include a plurality of regulation and policy rules that are issued by at least one government entity from at least one geographical region. These may be issued from a database, or pulled from a service, or implemented through natural language processing of web-content. Many viable options exist to implement the issuance of policies and regulations regarding data and processing of data known to those in the art.

Further aspects include a message-layer router 100 that is integrated into an existing layer two or layer three switch. This may be accomplished through firmware upgrades, plug-n-play hardware modules, or expansion cards. A software-based implementation of a message-layer router 100 is possible. It may be implemented as software-as-a-service (SaaS) offering, a mobile application, an executable file, or other software-distribution known to those in the art.

In some embodiments the network-bound message operates on the ten-layer standard open system interconnection model, wherein layers eight, nine, and ten are individuals, organizations, and governments, respectively. A message-layer router 100 furthermore may determine if all intermediary networked devices comply with the plurality of applied regulation and policy rules. A message-layer router 100 may also confirm if one or more users are compliant with the plurality of regulation and policy rules. A message-layer router 100 may also enforces routing based on cybersecurity threat indicators. As an example, an organization's cybersecurity software may insert alerts and detections to layer nine (organizations) as part of the organizations profile such that the system 100 may alter routing paths due to compromised or high-risk computing or network devices.

FIG. 2 is a flow diagram of an exemplary function of a regulatory message-layer message routing system in routing sensitive electronic messages per an embodiment 200. The message payload is generated by the message client and may include data comprised of one or more of a plurality of both sensitive or regulated information parts which in turn may include but are not limited to personal identification information such as bank account numbers, personal identification numbers (ex. a social security number, driver license number, or similar such code known to those skilled in the art), national security and defense information, or intellectual property information, just to name a few examples of the focus of the function of the embodiment, and non-regulated portions 201. During the creation of the message, the author may also indicate the entity meant to receive the message. The message client may then create a header specifying the source of the message as well as the contents of its payload in the message's payload level (OSI layers 8/9/10 (see FIG. 3A-C)) header, placing labels, also known as “keys” corresponding to <GOVERNMENT>, <ORGANIZATION>, and <INDVIDUAL> for the source router of the message and <CLASS>, <METHOD>, and <ORIGIN> describing the payload 202. Source router label information within the header and the payload description label information may then be used to address the message to a receiver router based upon the contents of the message header, the intended recipient and the current routing rules and policies stored within the embodiment 203. It is possible that the combination of the message header's source router and payload keys and the current embodiment's router rules and policies, no acceptable receiver router will be generated as the message may not be sent to the intended recipient. Under this condition when the message is bound to the source router by the header's sourceKey 204, this routing rule failure or some other routing rule or policy failure later determined 205 may lead 206 to the message not being sent 207 in which case the message client (FIG. 1, 105) may be informed. The nature and restrictions upon the payload of the message may also be determined based upon the embodiment's message client generated payload label designations 209 after the message is aggregated upon passing through the source router and bound to the payload router 208. Again, failure to comply with routing rules and policies based on payload contents may lead 210 to a failure of the message to progress to the intended recipient 211 for security, secrecy, or statutory restrictions, just to name a few examples of delivery failure categories familiar to those skilled in the art and handled by embodiments. Upon successful inspection of the payload key with all rules and policies fulfilled, the message may be sent to the recipient. This may be done by first sending the message to a receiving router for the organization, ignoring the receiving individual and may take multiple transitions between connected routing appliances (hops) to accomplish. These hops are pre-specified by embodiments with the header receiver label first pointing to the first intermediate hop router, which upon reaching the first intermediate hop router is stripped from the header and replaced by the label for the second intermediate hop router and so on, the process of substituting the receiving router label repeating until the ultimate destination router is reached. The path or router hops taken may be affected by other policy or router rules such as but not limited to restrictions on geographical zone or region or information protection protocols present, that each router must fulfill, for example “US”, “defense department controlled” or “HIPAA safeguards in place” to name just a few illustrative possibilities, the message may be restricted only to MLS routers in the US, restricted only to MLS routers controlled by the military, or only MLS routers running specific information handling or protection protocols, HIPAA protections, in the example. Upon reaching the originally designated receiving MLS router 212, often serving the organization to which the receiving individual belongs 213, the MLS header including all labels may be stripped the message forwarded, provided that individual is determined to be authorized to handle the sent information 212, using lookup for the recipient individual, the message is delivered using classic OSI layer 3 routing and layer 2 switching 214.

Certain embodiments may routinely encrypt the payload or handle payloads with task specific encoding such as but not limited to structured threat information expression (STIX), trusted automated exchange of indicator information (TAXII), and cyber observables (CybOX), among other similar offerings known to those skilled in the art.

FIG. 3A through FIG. 3C are diagrams showing an exemplary representation of the ten-layer OSI model. FIG. 3A The OSI stack has long served as a model of the abstract layers that make up a network system 301 from computing device application at layer seven through the physical media that may carry the encoded impulses at layer 1 each with a specific attributed function 302. Looking at FIG. 3A, briefly, layers 1, 2, and 3 which are often called the “media layers” 310 comprise the 1. The physical layer 311 a which is made up of the hardware, such as network cards, patch cables and repeaters that generates, carries and receives the information containing impulses 311 b; 2. The data link layer 312 a which represents the low level protocols such as Ethernet and token ring, just to name two, to ensure reliable transmission of data between two endpoints connected by physical layer devices, switches are placed at this layer 312 b; and 3. The network layer 313 a which manages network traffic between multiple network nodes including message packet routing and traffic control protocols, routers are placed at this layer 313 b. Looking at FIG. 3B, the next 4 layers may, together, be designated the “host layers 320” comprise: Layer 4, the transport layer 321 a which includes the protocols, such as udp and tcp that promote reliable transmission of data segments or datagrams between points on a network including connection initiation, segment acknowledgement, and re-transmit management 321 b; Layer 5, the session layer 322 a provides management of communication sessions in the form of back and forth transmission of information between two nodes on a network 322 b; Layer 6 the presentation layer 323 a, which manages form changes such as network level encryption/decryption, and compression/decompression of data 323 b; and Layer 7, the application layer 324 a which comprise the APIs allowing an operating system level process to exchange data with OSI layers below it 324 b. Some of these layers place informational headers pertaining to their activities onto the core payload data which travels over the network with the payload data packets and are removed as the transmission is delivered at the destination.

Recently, the need to safeguard message payload data has risen to the point that network-bound messages must be carefully tracked to fulfill regulations that arise at an organizational level such as but not limited to corporate practices, and policies, merchant customer data safeguarding concerns, and regional or global computer infrastructure maintenance, and incorruptible reporting of such. Governments including but not limited to the US and the European Union have passed laws aimed at protecting personal information and promoting such by stipulating significant penalties on those, corporate or otherwise, who do not adequately adhere to best practices or published minimums, a health care related example of this in the US being Health Insurance Portability and Accountability Act (HIPAA). This organizational and government attention as well as the recent legal atmosphere pertaining to security breaches of private information has solidified the need to strictly control the flow of network messages based upon payload rather than destination location. Looking at FIG. 3C this new requirement has resulted in the addition of three additional, top level layers to the OSI model, designated here as “Payload Layers 330” which comprises Layer 8, an individual layer 331 a, which manages parameters within a payload description pertaining to the individual sending a network transmission containing the payload and an individual receiving that network transmission 331 b. Layer 9, an organization layer 332 a, which manages parameters in a payload description that pertains to the sending organization and the receiving organization including authorization to the payload contents and rules and policies of both organizations that may modify network message transmission, including pathway and delivery 332 b. Finally, Layer 10, a “government layer” 333 a allows description of rules and policies that may relate to geographical or network topology defined “availability zones” for where specific information may be transmitted and what safeguards must accompany the payload information 333 b.

FIG. 4 is a comparison of select features of common routers and an embodiment router 400. To date, virtually all routers called to mind when discussing a computing device network 410 from a small wide area network to those that serve the internet, perform by reading the OSI layer 3 packet header 411 and determining to which of a plurality of known routers 413 to forward that packet using the destination IP address, or a suitable analog depending on the networking system in use, without regard to payload contents. Multiple improvements on this basic description have arisen, but the majority have been in response to speed and network segment congestion issues or aimed at more rudimentary security matters as preventing injection of malicious routers into the routing tables used to determine a next “hop” in a delivery path. For the most part current common routers retain their heritage of message openness with no payload security borne from a time when the need for such security was not at all foreseen. The focus of the common router is to forward a network packet from a source location to a destination location 412 optimizing speed and network congestion using a dynamic list of downstream routers which may span a limited number of hops in the total packet delivery path 413. This current routing system is not suited to the current information security climate where significant effort is made by a plurality of individuals, groups and even governments to misappropriate sensitive personal, business, and national data. Nor does it provide any mechanism to assure and confirm compliance with the plurality of regulations both at the organizational, such as but not limited to corporate, hospital, and banking; or government level issued to combat private information theft.

Embodiment MLS routers 420 may route messages through a network based upon the payload contents and any regulatory routing rules or policies associated with that payload and thus may be considered to work on OSI layers 8, 9 and 10 that have been added to the OSI model to describe the activities of networking protocols and hardware that inspect message payload related restrictions, credentials or instructions pertaining to individuals (OSI layer 8), organizations (OSI layer 9) and governments (OSI layer 10) 421. Systems of this type are engineered to accept, under sets of stringent access rules, labels which may be in the form of a unique alphanumeric token defining specific entities such as individuals, organizations, countries, geographical regions or zones of identical message payload regulatory and policy requirements in addition to other like entities familiar to those skilled in the art, which may be further grouped based on like payload handling authorizations (For example all health care professionals at a hospital who have up-to-date HIPAA privacy training credentials may all have the ability to receive network message payloads marked with a label designating the payload “HIPAA regulated,” provided the hospital is also HIPAA accredited, or all military personnel with certain clearances and affiliation to a specific project may have the ability to receive network messages with the label “SECR!!12538,” possibly also assuming that the individual is attempting to access the information in an “availability zone”, geographical, or otherwise, where viewing is allowed 422. In addition to what may be considered “credentialing functions” of individuals, organizations and availability zones, embodiments also comprise an extensive body of programming at least some of which attaches identifying labels for entities, groups of entities, and payload information regulations and policies to specific actions and effects of those regulations and policies to, for example, programmatically ensure that a message payload marked with the label such as “EU” is only routed through European Union compliant routers 423. As embodiments are highly distributed, many vetted operators at multiple embodiment served locations may be involved in entering both credential type and programming data.

FIG. 5A and FIG. 5B are process diagrams of a simplified OSI 8/9/10 message header and example programming structure per an embodiment 500. FIG. 5A: Given a network with a simplified embodiment OSI layer 8/9/10 type header 510 presented here, we have a message being sent by N. Kean, MD 515 d at ABC1234 Memorial Hospital 515 c which is in the United States 515 b (US.ABC1234MHOSP.NKEANMD) as indicated by the sourceKey 515 a. The message payload is a patient's record 520 b, the action is categorized as a transfer 520 c and the initiator may be a workstation: STDOUT 520 d as is indicated by the messages payloadKey (PRECORD.TRANSFER.STDOUT) 520 a. The message and is payload is being sent to another doctor J. Wilson, MD and a remote embodiment served hospital WXYZ4321 Memorial Hospital which is also in the United States as is indicated by the receiverKey 525 a in the message's header: (US.WXYZ4321MHOSPJWILSONMD) 525 b, 525 c, 525 d. Other labels relevant to the message payload are also included header as activePolicies 530 a, these include the label indicating the payload is subject to HIPAA law stipulations “HIPAA” 530 b, that the message and its payload will be entirely routed by US based routers “US” 530 c and that the system will internally encrypt the message during routing 530 d. Some of these labels may not be dictated by the payload but present due to embodiment defined best practices. It should be noted that the header is devised to best illustrate some of the important features of the embodiment and may not be found in a single header or, in some cases, any header generated by a preferred embodiment.

Given the sample MLS compliant message header, one may illustrate some of the function archetypes for select modules of an embodiment. From the messaging client and from information included by the author of the network message, including the nature of the source router key 515 b-d and payload key 520 b-d specified by the messaging client, to be sent as well as embodiment internal programming, the MLS addresser module (see FIG. 1, 110) 550 may add the label for the receiving router: .addReceiverKey( ) and then sends the message. The source router exchange 115, 551 may perform several pre-programmed tests and then binds the message to the source router 160, 552 which may be implemented (.of(“US.ABC1234MHOSP.*”)) and configured (.if(“patient-health-record”)) on-the-fly in software in certain embodiments. The message may then be passed to a payload exchange module 165, 553 which may perform further payload specific tests and then bind the message to the appropriate payload router 170, 554, 555, As illustrated in FIG. 5B, 590, which again may be implemented (.of(“PRECORD.TRANSFER.STDOUT”)) and configured (.if(policy.is(“US”)), .if(policy.is(“HIPAA)) in software as the need for the router arises. Also illustrated is a modular feature of embodiments which allows programming for payloads with complex regulatory and policy specifications to be assembled from multiple rules 554, 555 simplifying maintenance of individual regulation or policy driven programs and the troubleshooting of non-functional modules. Programming of receiver exchange module 175, 556 and implementation as well as configuration of the receiver router 180, 557 follow the previously shown standard with ultimate delivery depending upon the credential labels of the receiving individual matching the required regulatory minimums of the payload (.if(receiveind.is.policyTrusted(JWILSONMD)). Dependent on the embodiment, policy testing for the ultimate receiving entity may be performed in the upstream payload exchange module (FIG. 1, 185).

It should be understood that the skeletal programming snippets shown in this figure represent the minimal amount of archetype code needed to introduce each salient point and are not at all reflective of the programming complexity or function diversity expected to be present in a functional embodiment.

FIG. 6 is a diagram illustrating the use of routing regulatory labels to create availability zones 600. One way of characterizing the areas where message payloads governed by equivalent regulations and policies is through the construct of availability zones. Availability zones may be a large geographical region such as a country, for example the United States 601, Mexico 602 and Canada 603 just to list three of the plurality known to those skilled in the art. Other availability zones may result from the presence of a specific organization such as but in no way limited to military installations 610 a, 610 b, 610 c and 690 which may possess the ability to process defense regulated messages 615 a, 615 b, 615 c or health care facilities 620 a, 620 b, 620 c which may occupy geography as small as a single building and be equipped to process HIPAA regulated messages 625 a, 625 b, 625 c. Based upon these availability zones and MLS actionable labels, messages may be tightly controlled for transmission and delivery. A USA (US) defense (DEF) regulated and labeled message 617 with an MLS header 617 a may thus be sent to USA military installations such as but not limited to bases and buildings 610 a-c over MLS service routers 615 a, 615 b, 615 c. When employed sensitive US defense (DEF) messages 617 may be successfully sent from the source router 615 a to one or more destination receiver routers 615 b and 615 c within other US DEF availability zones 610 b, 610 c. Messages with US and DEF labels, signifying they are regulated by rules for US and DEF will not be sent 662 to a DEF availability zone for Mexico (DEF MEX) 690 as the MLS router 695 has only the credentials imparted by “DEF.” The same message will not be sent 661 to a US HIPPAA compliant availability zone 620 a as the HIPAA MLS router in the zone lacks DEF authorization. Similarly, a health care message payload 655 with a MLS compliant header 655 a will be successfully sent by a HIPAA compliant MLS source router 625 c to a HIPAA compliant MLS router 625 b at a second HIPAA credentialed availability zone 620 b but not to a US DEF authorized availability zone 610 c which lacks HIPAA data handling protocols 663. Embodiments may route messages through compliant MLS router exclusive paths 615 a to 615 b to 615 c when intermediate hops are required. Failed message transmission attempts 661, 662, 663 would fail prior to transmission out of the source availability zones. Partial paths in those samples were solely to illustrate the intended, failing target.

Hardware Architecture

Generally, the techniques disclosed herein may be implemented on hardware or a combination of software and hardware. For example, they may be implemented in an operating system kernel, in a separate user process, in a library package bound into network applications, on a specially constructed machine, on an application-specific integrated circuit (ASIC), or on a network interface card.

Software/hardware hybrid implementations of at least some of the embodiments disclosed herein may be implemented on a programmable network-resident machine (which should be understood to include intermittently connected network-aware machines) selectively activated or reconfigured by a computer program stored in memory. Such network devices may have multiple network interfaces that may be configured or designed to utilize different types of network communication protocols. A general architecture for some of these machines may be described herein in order to illustrate one or more exemplary means by which a given unit of functionality may be implemented. According to specific embodiments, at least some of the features or functionalities of the various embodiments disclosed herein may be implemented on one or more general-purpose computers associated with one or more networks, such as for example an end-user computer system, a client computer, a network server or other server system, a mobile computing device (e.g., tablet computing device, mobile phone, smartphone, laptop, or other appropriate computing device), a consumer electronic device, a music player, or any other suitable electronic device, router, switch, or other suitable device, or any combination thereof. In at least some embodiments, at least some of the features or functionalities of the various embodiments disclosed herein may be implemented in one or more virtualized computing environments (e.g., network computing clouds, virtual machines hosted on one or more physical computing machines, or other appropriate virtual environments).

Referring now to FIG. 7, there is shown a block diagram depicting an exemplary computing device 10 suitable for implementing at least a portion of the features or functionalities disclosed herein. Computing device 10 may be, for example, any one of the computing machines listed in the previous paragraph, or indeed any other electronic device capable of executing software- or hardware-based instructions according to one or more programs stored in memory. Computing device 10 may be configured to communicate with a plurality of other computing devices, such as clients or servers, over communications networks such as a wide area network a metropolitan area network, a local area network, a wireless network, the Internet, or any other network, using known protocols for such communication, whether wireless or wired.

In one embodiment, computing device 10 includes one or more central processing units (CPU) 12, one or more interfaces 15, and one or more busses 14 (such as a peripheral component interconnect (PCI) bus). When acting under the control of appropriate software or firmware, CPU 12 may be responsible for implementing specific functions associated with the functions of a specifically configured computing device or machine. For example, in at least one embodiment, a computing device 10 may be configured or designed to function as a server system utilizing CPU 12, local memory 11 and/or remote memory 16, and interface(s) 15. In at least one embodiment, CPU 12 may be caused to perform one or more of the different types of functions and/or operations under the control of software modules or components, which for example, may include an operating system and any appropriate applications software, drivers, and the like.

CPU 12 may include one or more processors 13 such as, for example, a processor from one of the Intel, ARM, Qualcomm, and AMD families of microprocessors. In some embodiments, processors 13 may include specially designed hardware such as application-specific integrated circuits (ASICs), electrically erasable programmable read-only memories (EEPROMs), field-programmable gate arrays (FPGAs), and so forth, for controlling operations of computing device 10. In a specific embodiment, a local memory 11 (such as non-volatile random access memory (RAM) and/or read-only memory (ROM), including for example one or more levels of cached memory) may also form part of CPU 12. However, there are many different ways in which memory may be coupled to system 10. Memory 11 may be used for a variety of purposes such as, for example, caching and/or storing data, programming instructions, and the like. It should be further appreciated that CPU 12 may be one of a variety of system-on-a-chip (SOC) type hardware that may include additional hardware such as memory or graphics processing chips, such as a Qualcomm SNAPDRAGON™ or Samsung EXYNOS™ CPU as are becoming increasingly common in the art, such as for use in mobile devices or integrated devices.

As used herein, the term “processor” is not limited merely to those integrated circuits referred to in the art as a processor, a mobile processor, or a microprocessor, but broadly refers to a microcontroller, a microcomputer, a programmable logic controller, an application-specific integrated circuit, and any other programmable circuit.

In one embodiment, interfaces 15 are provided as network interface cards (NICs). Generally, NICs control the sending and receiving of data packets over a computer network; other types of interfaces 15 may for example support other peripherals used with computing device 10. Among the interfaces that may be provided are Ethernet interfaces, frame relay interfaces, cable interfaces, DSL interfaces, token ring interfaces, graphics interfaces, and the like. In addition, various types of interfaces may be provided such as, for example, universal serial bus (USB), Serial, Ethernet, FIREWIRE™, THUNDERBOLT™, PCI, parallel, radio frequency (RF), BLUETOOTH™, near-field communications (e.g., using near-field magnetics), 802.11 (WiFi), frame relay, TCP/IP, ISDN, fast Ethernet interfaces, Gigabit Ethernet interfaces, Serial ATA (SATA) or external SATA (ESATA) interfaces, high-definition multimedia interface (HDMI), digital visual interface (DVI), analog or digital audio interfaces, asynchronous transfer mode (ATM) interfaces, high-speed serial interface (HSSI) interfaces, Point of Sale (POS) interfaces, fiber data distributed interfaces (FDDIs), and the like. Generally, such interfaces 15 may include physical ports appropriate for communication with appropriate media. In some cases, they may also include an independent processor (such as a dedicated audio or video processor, as is common in the art for high-fidelity A/V hardware interfaces) and, in some instances, volatile and/or non-volatile memory (e.g., RAM).

Although the system shown and described above illustrates one specific architecture for a computing device 10 for implementing one or more of the inventions described herein, it is by no means the only device architecture on which at least a portion of the features and techniques described herein may be implemented. For example, architectures having one or any number of processors 13 may be used, and such processors 13 may be present in a single device or distributed among any number of devices. In one embodiment, a single processor 13 handles communications as well as routing computations, while in other embodiments a separate dedicated communications processor may be provided. In various embodiments, different types of features or functionalities may be implemented in a system according to the invention that includes a client device (such as a tablet device or smartphone running client software) and server systems (such as a server system described in more detail below).

Regardless of network device configuration, the system of the present invention may employ one or more memories or memory modules (such as, for example, remote memory block 16 and local memory 11) configured to store data, program instructions for the general-purpose network operations, or other information relating to the functionality of the embodiments described herein (or any combinations of the above). Program instructions may control execution of or comprise an operating system and/or one or more applications, for example. Memory 16 or memories 11, 16 may also be configured to store data structures, configuration data, encryption data, historical system operations information, or any other specific or generic non-program information described herein.

Because such information and program instructions may be employed to implement one or more systems or methods described herein, at least some network device embodiments may include nontransitory machine-readable storage media, which, for example, may be configured or designed to store program instructions, state information, and the like for performing various operations described herein. Examples of such nontransitory machine-readable storage media include, but are not limited to, magnetic media such as hard disks, floppy disks, and magnetic tape; optical media such as CD-ROM disks; magneto-optical media such as optical disks, and hardware devices that are specially configured to store and perform program instructions, such as read-only memory devices (ROM), flash memory (as is common in mobile devices and integrated systems), solid state drives (SSD) and “hybrid SSD” storage drives that may combine physical components of solid state and hard disk drives in a single hardware device (as are becoming increasingly common in the art with regard to personal computers), memristor memory, random access memory (RAM), and the like. It should be appreciated that such storage means may be integral and non-removable (such as RAM hardware modules that may be soldered onto a motherboard or otherwise integrated into an electronic device), or they may be removable such as swappable flash memory modules (such as “thumb drives” or other removable media designed for rapidly exchanging physical storage devices), “hot-swappable” hard disk drives or solid state drives, removable optical storage discs, or other such removable media, and that such integral and removable storage media may be utilized interchangeably. Examples of program instructions include both object code, such as may be produced by a compiler, machine code, such as may be produced by an assembler or a linker, byte code, such as may be generated by for example a JAVATM compiler and may be executed using a Java virtual machine or equivalent, or files containing higher level code that may be executed by the computer using an interpreter (for example, scripts written in Python, Perl, Ruby, Groovy, or any other scripting language).

In some embodiments, systems according to the present invention may be implemented on a standalone computing system. Referring now to FIG. 8, there is shown a block diagram depicting a typical exemplary architecture of one or more embodiments or components thereof on a standalone computing system. Computing device 20 includes processors 21 that may run software that carry out one or more functions or applications of embodiments of the invention, such as for example a client application 24. Processors 21 may carry out computing instructions under control of an operating system 22 such as, for example, a version of Microsoft's WINDOWS™ operating system, Apple's Mac OS/X or iOS operating systems, some variety of the Linux operating system, Google's ANDROID™ operating system, or the like. In many cases, one or more shared services 23 may be operable in system 20, and may be useful for providing common services to client applications 24. Services 23 may for example be WINDOWS™ services, user-space common services in a Linux environment, or any other type of common service architecture used with operating system 21. Input devices 28 may be of any type suitable for receiving user input, including for example a keyboard, touchscreen, microphone (for example, for voice input), mouse, touchpad, trackball, or any combination thereof. Output devices 27 may be of any type suitable for providing output to one or more users, whether remote or local to system 20, and may include for example one or more screens for visual output, speakers, printers, or any combination thereof. Memory 25 may be random-access memory having any structure and architecture known in the art, for use by processors 21, for example to run software. Storage devices 26 may be any magnetic, optical, mechanical, memristor, or electrical storage device for storage of data in digital form (such as those described above). Examples of storage devices 26 include flash memory, magnetic hard drive, CD-ROM, and/or the like.

In some embodiments, systems of the present invention may be implemented on a distributed computing network, such as one having any number of clients and/or servers. Referring now to FIG. 9, there is shown a block diagram depicting an exemplary architecture 30 for implementing at least a portion of a system according to an embodiment of the invention on a distributed computing network. According to the embodiment, any number of clients 33 may be provided. Each client 33 may run software for implementing client-side portions of the present invention; clients may comprise a system 20 such as that illustrated above. In addition, any number of servers 32 may be provided for handling requests received from one or more clients 33. Clients 33 and servers 32 may communicate with one another via one or more electronic networks 31, which may be in various embodiments any of the Internet, a wide area network, a mobile telephony network (such as CDMA or GSM cellular networks), a wireless network (such as WiFi, Wimax, LTE, and so forth), or a local area network (or indeed any network topology known in the art; the invention does not prefer any one network topology over any other). Networks 31 may be implemented using any known network protocols, including for example wired and/or wireless protocols.

In addition, in some embodiments, servers 32 may call external services 37 when needed to obtain additional information, or to refer to additional data concerning a particular call. Communications with external services 37 may take place, for example, via one or more networks 31. In various embodiments, external services 37 may comprise web-enabled services or functionality related to or installed on the hardware device itself. For example, in an embodiment where client applications 24 are implemented on a smartphone or other electronic device, client applications 24 may obtain information stored in a server system 32 in the cloud or on an external service 37 deployed on one or more of a particular enterprise's or user's premises.

In some embodiments of the invention, clients 33 or servers 32 (or both) may make use of one or more specialized services or appliances that may be deployed locally or remotely across one or more networks 31. For example, one or more databases 34 may be used or referred to by one or more embodiments of the invention. It should be understood by one having ordinary skill in the art that databases 34 may be arranged in a wide variety of architectures and using a wide variety of data access and manipulation means. For example, in various embodiments one or more databases 34 may comprise a relational database system using a structured query language (SQL), while others may comprise an alternative data storage technology such as those referred to in the art as “NoSQL” (for example, Hadoop Cassandra, Google BigTable, and so forth). In some embodiments, variant database architectures such as column-oriented databases, in-memory databases, clustered databases, distributed databases, or even flat file data repositories may be used according to the invention. It will be appreciated by one having ordinary skill in the art that any combination of known or future database technologies may be used as appropriate, unless a specific database technology or a specific arrangement of components is specified for a particular embodiment herein. Moreover, it should be appreciated that the term “database” as used herein may refer to a physical database machine, a cluster of machines acting as a single database system, or a logical database within an overall database management system. Unless a specific meaning is specified for a given use of the term “database”, it should be construed to mean any of these senses of the word, all of which are understood as a plain meaning of the term “database” by those having ordinary skill in the art.

Similarly, most embodiments of the invention may make use of one or more security systems 36 and configuration systems 35. Security and configuration management are common information technology (IT) and web functions, and some amount of each are generally associated with any IT or web systems. It should be understood by one having ordinary skill in the art that any configuration or security subsystems known in the art now or in the future may be used in conjunction with embodiments of the invention without limitation, unless a specific security 36 or configuration system 35 or approach is specifically required by the description of any specific embodiment.

FIG. 10 shows an exemplary overview of a computer system 40 as may be used in any of the various locations throughout the system. It is exemplary of any computer that may execute code to process data. Various modifications and changes may be made to computer system 40 without departing from the broader scope of the system and method disclosed herein. Central processor unit (CPU) 41 is connected to bus 42, to which bus is also connected memory 43, nonvolatile memory 44, display 47, input/output (I/O) unit 48, and network interface card (NIC) 53. I/O unit 48 may, typically, be connected to keyboard 49, pointing device 50, hard disk 52, and real-time clock 51. NIC 53 connects to network 54, which may be the Internet or a local network, which local network may or may not have connections to the Internet. Also shown as part of system 40 is power supply unit 45 connected, in this example, to a main alternating current (AC) supply 46. Not shown are batteries that could be present, and many other devices and modifications that are well known but are not applicable to the specific novel functions of the current system and method disclosed herein. It should be appreciated that some or all components illustrated may be combined, such as in various integrated applications, for example Qualcomm or Samsung system-on-a-chip (SOC) devices, or whenever it may be appropriate to combine multiple capabilities or functions into a single hardware device (for instance, in mobile devices such as smartphones, video game consoles, in-vehicle computer systems such as navigation or multimedia systems in automobiles, or other integrated hardware devices).

In various embodiments, functionality for implementing systems or methods of the present invention may be distributed among any number of client and/or server components. For example, various software modules may be implemented for performing various functions in connection with the present invention, and such modules may be variously implemented to run on server and/or client.

The skilled person will be aware of a range of possible modifications of the various embodiments described above. Accordingly, the present invention is defined by the claims and their equivalents. 

What is claimed is:
 1. A message routing system for global policy enforcement comprising: a message-layer router comprising at least a plurality of programming instructions stored in a memory of, and operating on at least one processor of, a computing device, wherein the plurality of programming instructions, when operating on the at least one processor, cause the computing device to: store a plurality of regulations and policy rules regarding a plurality of individuals, organizations, and governments; search for and implement updates to the plurality of regulations and policy rules; receive a network-bound message from a first networked device, the network-bound message intended for a second networked device; inspect the network-bound message for attributes related to individuals, organizations, and governments; apply the plurality of regulation and policy rules to the network-bound message, wherein the applied rules correspond to the attributes related to individuals, organizations, and governments in the network-bound message; confirm that the first networked device and the second networked device comply with the regulation and policy rules applied to the network-bound message; and if confirmation is successful, release the network-bound message for transmission to the second networked device.
 2. The system of claim 1, further comprising a ledger to immutably record changes to and transactions of the network-bound message.
 3. The system of claim 1, wherein at least a portion of the plurality of regulation and policy rules are issued by at least one government entity from at least one geographical region.
 4. The system of claim 1, wherein the message-layer router is integrated into a layer two or layer three switch.
 5. The system of claim 1, wherein the network-bound message operates on the ten-layer standard open system interconnection model.
 6. The system of claim 1, wherein the message-layer router determines if all intermediary networked devices comply with the plurality of applied regulation and policy rules.
 7. The system of claim 1, wherein message-layer router confirms if one or more users are compliant with the plurality of regulation and policy rules.
 8. The system of claim 1, wherein the message-layer router enforces routing based on cybersecurity threat indicators.
 9. The system of claim 1, wherein the message-layer router is a software-based application.
 10. The system of claim 1, wherein the message-layer router also reads layers two and three of the open interconnection system model.
 11. A method for message routing for global policy enforcement comprising the steps of: storing a plurality of regulations and policy rules regarding a plurality of individuals, organizations, and governments; searching for and implementing updates to the plurality of regulations and policy rules; receiving a network-bound message from a first networked device, the network-bound message intended for a second networked device; inspecting the network-bound message for attributes related to individuals, organizations, and governments; applying the plurality of regulation and policy rules to the network-bound message, wherein the applied rules correspond to the attributes related to individuals, organizations, and governments in the network-bound message; confirming that the first networked device and the second networked device comply with the regulation and policy rules applied to the network-bound message; and if confirmation is successful, releasing the network-bound message for transmission to the second networked device.
 12. The method of claim 11, further comprising a ledger to immutably record changes to and transactions of the network-bound message.
 13. The method of claim 11, wherein at least a portion of the plurality of regulation and policy rules are issued by at least one government entity from at least one geographical region.
 14. The method of claim 11, wherein the message-layer router is integrated into a layer two or layer three switch.
 15. The method of claim 11, wherein the network-bound message operates on the ten-layer standard open system interconnection model.
 16. The method of claim 11, wherein the message-layer router determines if all intermediary networked devices comply with the plurality of applied regulation and policy rules.
 17. The method of claim 11, wherein message-layer router confirms if one or more users are compliant with the plurality of regulation and policy rules.
 18. The method of claim 11, wherein the message-layer router enforces routing based on cybersecurity threat indicators.
 19. The method of claim 11, wherein the message-layer router is a software-based application.
 20. The method of claim 11, wherein the message-layer router also reads layers two and three of the open interconnection system model. 